Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

System.Text.Json 8.0.4 has security vulnerability #13857

Closed
dtivel opened this issue Oct 15, 2024 · 0 comments · Fixed by NuGet/NuGet.Client#6101
Closed

System.Text.Json 8.0.4 has security vulnerability #13857

dtivel opened this issue Oct 15, 2024 · 0 comments · Fixed by NuGet/NuGet.Client#6101
Assignees
Labels
Priority:2 Issues for the current backlog. Tenet:Security Type:Engineering product/infrastructure work/not a customer bug/feature/DCR

Comments

@dtivel
Copy link
Contributor

dtivel commented Oct 15, 2024

NuGet Product Used

dotnet.exe, MSBuild.exe, NuGet.exe, Visual Studio Package Management UI, Visual Studio Package Manager Console, NuGet SDK

Product Version

latest

Worked before?

No response

Impact

None

Repro Steps & Context

NuGet.Client references System.Text.Json 8.0.4:
https://github.com/NuGet/NuGet.Client/blob/fd6880078a435aa63fb1290e9bc58fb8dea6a4fd/Directory.Packages.props#L8

This version has a security vulnerability: GHSA-8g4q-xg66-9fp4

Verbose Logs

No response

@dtivel dtivel self-assigned this Oct 15, 2024
@jeffkl jeffkl added Priority:2 Issues for the current backlog. Type:Engineering product/infrastructure work/not a customer bug/feature/DCR Tenet:Security and removed Type:Bug Triage:Untriaged labels Oct 15, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Priority:2 Issues for the current backlog. Tenet:Security Type:Engineering product/infrastructure work/not a customer bug/feature/DCR
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants